industry-performance-snapshot
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalyreferences/mcp-setup.md
LOWAnomalyLOW
references/mcp-setup.md
The supplied fragment is setup documentation and contains no direct evidence of malware. It does present supply-chain and credential-exposure risks: it executes a remotely downloaded shell script, runs an npm package through npx with automatic approval, uses an unpinned latest tag, and places API keys in command lines or plaintext configuration. Review the package identity, provenance, lock or pin an audited version, verify integrity, and store the API key using a protected secret mechanism before deployment.
Confidence: 98%Severity: 58%
Audit Metadata